Executive Summary

Informations
Name CVE-2024-55630 First vendor Publication 2025-02-07
Vendor Cve Last vendor Modification 2025-02-10

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Joplin's HTML sanitizer allows the `name` attribute to be specified. If `name` is set to the same value as an existing `document` property (e.g. `querySelector`), that property is replaced with the element. This vulnerability's only known impact is denial of service. The note viewer fails to refresh until closed and re-opened with a different note. This issue has been addressed in version 3.2.8 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-55630

Sources (Detail)

https://en.wikipedia.org/wiki/DOM_clobbering
https://github.com/laurent22/joplin/commit/e70efcbd60ce62f06e77c183b362c74e63...
https://github.com/laurent22/joplin/security/advisories/GHSA-5cch-jr52-qffh
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
Date Informations
2025-02-11 17:20:30
  • Multiple Updates
2025-02-08 05:20:29
  • First insertion